BehaviorAnalytics stopped collecting FailedLogon events

Dmitriy Kolesnikov 11 Reputation points
2022-05-02T14:38:39.777+00:00

Hi there.

Starting from April 2022 we experience the situation when the query to the BehaviorAnalytics table doesn't select any records with the ActivityType containing 'FailedLogOn'. And there are no records like that if you select the records without any filters.

I checked all connected logs and everything looks enabled.

Could you please guide me on how to fix this?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Dmitriy Kolesnikov 11 Reputation points
    2022-05-02T15:41:24.787+00:00

    It seems the issue is caused by the issue with the Azure Premium P1/P2 license. Recently we updated the licenses for all in the company and some of those licenses don't work properly with Sentinel.

    0 comments No comments

  2. Andrew Blumhardt 10,066 Reputation points Microsoft Employee
    2022-05-02T15:46:44.003+00:00

    I would start by checking the source tables for activity. Make sure your AAD Audit and Signin Logs are flowing. Maybe reset the UEBA settings. It may need reauthorization.

    https://learn.microsoft.com/en-us/azure/sentinel/enable-entity-behavior-analytics

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.